High severityNVD Advisory· Published Sep 14, 2026
CVE-2026-68489
CVE-2026-68489
Description
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Affected products
2- Range: <2.5.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.